Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian Linux Kernel: DSA-4843-1 Moderate Privilege Escalation Risk

debian
Calendar Grey February 1, 2021
Debian Logo
Multiple vulnerabilities in the Debian Linux kernel need urgent fixes and patches to maintain system security.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks

Summary

CVE-2020-27815

A flaw was reported in the JFS filesystem code allowing a local
attacker with the ability to set extended attributes to cause a
denial of service.

CVE-2020-27825

Adam 'pi3' Zabrocki reported a use-after-free flaw in the ftrace
ring buffer resizing logic due to a race condition, which could
result in denial of service or information leak.

CVE-2020-27830

Shisong Qin reported a NULL pointer dereference flaw in the Speakup
screen reader core driver.

CVE-2020-28374

David Disseldorp discovered that the LIO SCSI target implementation
performed insufficient checking in certain XCOPY requests. An
attacker with access to a LUN and knowledge of Unit Serial Number
assignments can take advantage of this flaw to read and write to any
LIO backstore, regardless of the SCSI transport settings.

CVE-2020-29568 (XSA-349)

Michael Kurth and Pawel Wieczorkiewicz reported that frontends can
trigger OOM in backends by updating a watched path.

CVE-2020-2...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Package: linux
CVE ID: CVE-2020-27815 CVE-2020-27825 CVE-2020-27830 CVE-2020-28374

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here